Onedev Project maintains a Git-based DevOps and continuous integration platform that, despite narrow product scope, occupies a prominent position in the development infrastructure landscape. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, clustering around injection flaws, unsafe deserialization, path traversal, code injection, and information disclosure—weakness classes that reflect the risks inherent to a web-facing platform that processes untrusted code and build artifacts. Defenders should treat Onedev advisories as high-priority for any exposed instances and monitor for exploitation signals; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Onedev Project over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21242CRITICAL OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet | Jan 15, 2021 | 9.8 | 73 | NO | NO |
CVE-2021-21246HIGH OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that only administrators can list use | Jan 15, 2021 | 7.5 | 62 | NO | YES |
CVE-2021-21243CRITICAL OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted data from the request body. These | Jan 15, 2021 | 9.8 | 61 | NO | NO |
CVE-2024-45309HIGH OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev s | Oct 21, 2024 | 7.5 | 57 | NO | YES |
CVE-2021-21251HIGH OneDev is an all-in-one devops platform. In OneDev before version 4.0.3 there is a critical "zip slip" vulnerability. This issue may lead to arbitrary file write. The KubernetesRes | Jan 15, 2021 | 8.8 | 33 | NO | NO |
CVE-2022-39205CRITICAL Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthenticated users can take over a OneDev instance if there is no pr | Sep 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-21245CRITICAL OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified lo | Jan 15, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-21244CRITICAL OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message t | Jan 15, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-21249HIGH OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote code execution. In order to par | Jan 15, 2021 | 8.8 | 29 | NO | NO |
CVE-2021-21248HIGH OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. InputSpec is used to define para | Jan 15, 2021 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Onedev Project.
Media articles that mention a CVE ID that affects a product developed by Onedev Project — matched by CVE ID, not by vendor name.